Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > UK VOIP > Grandstream BT 101 phone hacked?

Reply
Thread Tools

Grandstream BT 101 phone hacked?

 
 
Tom
Guest
Posts: n/a
 
      07-18-2005
Hi,

I have a SIP phone (Grandstream BT 101), which I use with Sipgate. However,
yesterday, when I tried to use it, it wouldn't work. I went to the settings
page of the phone, and discovered that the connection details had been
changed. The provider was no longer Sipgate but europasstelecom.com (many
settings had been changed).

I wonder if this is a bug following a self-firmware update, or if some
company hacked the phone to change the provider...

Tom


 
Reply With Quote
 
 
 
 
Ivor Jones
Guest
Posts: n/a
 
      07-18-2005
Tom wrote:
> Hi,
>
> I have a SIP phone (Grandstream BT 101), which I use with Sipgate.
> However, yesterday, when I tried to use it, it wouldn't work. I
> went to the settings page of the phone, and discovered that the
> connection details had been changed. The provider was no longer
> Sipgate but europasstelecom.com (many settings had been changed).
>
> I wonder if this is a bug following a self-firmware update, or if
> some company hacked the phone to change the provider...
>
> Tom


Interesting, not come across that before. I'll make some enquiries..! Had
the firmware recently updated..?

Ivor


 
Reply With Quote
 
 
 
 
Paul D.Smith
Guest
Posts: n/a
 
      07-18-2005
Please let us know what you find out! Hacking SIP phones could be a whole
new area of hurt for comsumers!

Although this shouldn't be able to hurt you commerically, it would allow
someone to fish for all your friends numbers, and could even listen in on
your conversations.

Anyone for secured media?...

Paul DS.


 
Reply With Quote
 
Ian
Guest
Posts: n/a
 
      07-18-2005

"Tom" <> wrote in message
news:...
> Hi,
>
> I have a SIP phone (Grandstream BT 101), which I use with Sipgate.

However,
> yesterday, when I tried to use it, it wouldn't work. I went to the

settings
> page of the phone, and discovered that the connection details had been
> changed. The provider was no longer Sipgate but europasstelecom.com (many
> settings had been changed).
>
> I wonder if this is a bug following a self-firmware update, or if some
> company hacked the phone to change the provider...
>
> Tom
>

Hi.

Ok, did you buy this set new? And when you programed it you set the tftp
server to 0.0.0.0 or an address on your network and changed the password.
If not and you left the tftp server address in when it reboots it will look
for the tftp server and update settings as nesesary.
To have "Hacked" it you would have needed port80 open and pointing at the
phone..
I very much doubt its been hacked.

What is even odder is that europasstelecom dont seem to have launched a
service yet!!!! and it looks like a MLM scheme as well, so any type of
advertising is good for dodgy agents.......even just getting the name
outthere....

Ian


 
Reply With Quote
 
Paul D.Smith
Guest
Posts: n/a
 
      07-18-2005
> Ok, did you buy this set new? And when you programed it you set the tftp
> server to 0.0.0.0 or an address on your network and changed the password.
> If not and you left the tftp server address in when it reboots it will

look
> for the tftp server and update settings as nesesary.
> To have "Hacked" it you would have needed port80 open and pointing at the
> phone..
> I very much doubt its been hacked.
>
> What is even odder is that europasstelecom dont seem to have launched a
> service yet!!!! and it looks like a MLM scheme as well, so any type of
> advertising is good for dodgy agents.......even just getting the name
> outthere....
>


But does upgrading the firmware loose all customer settings? Is there no
facility for upgrading but restoring user configuration?

Paul DS.


 
Reply With Quote
 
Andrew Gabriel
Guest
Posts: n/a
 
      07-18-2005
In article <42db928c$0$13702$> ,
"Paul D.Smith" <> writes:
>But does upgrading the firmware loose all customer settings? Is there no
>facility for upgrading but restoring user configuration?


Much to my surprise, upgrading (and then downgrading again)
my sipura spa-3000 didn't lose any settings.

--
Andrew Gabriel

 
Reply With Quote
 
Ian
Guest
Posts: n/a
 
      07-18-2005

"Paul D.Smith" <> wrote in message
news:42db928c$0$13702$. net...
> > Ok, did you buy this set new? And when you programed it you set the tftp
> > server to 0.0.0.0 or an address on your network and changed the

password.
> > If not and you left the tftp server address in when it reboots it will

> look
> > for the tftp server and update settings as nesesary.
> > To have "Hacked" it you would have needed port80 open and pointing at

the
> > phone..
> > I very much doubt its been hacked.
> >
> > What is even odder is that europasstelecom dont seem to have launched a
> > service yet!!!! and it looks like a MLM scheme as well, so any type of
> > advertising is good for dodgy agents.......even just getting the name
> > outthere....
> >

>
> But does upgrading the firmware loose all customer settings? Is there no
> facility for upgrading but restoring user configuration?
>

No. But settings can be part of the TFTP process, more info here
http://tanesha.net/Wiki/GratissipTftpd.html. Personly this is the first time
I have heard of a GS being "hacked" and as I mentioned its strange that the
company mentioned doesnt have a service just a MLM scheme of types running.

Ian


 
Reply With Quote
 
Tom
Guest
Posts: n/a
 
      07-19-2005
Hi,

The software was upgraded automatically apparently. I bought the phone from
new, and originally went to a single page to put my settings. I am using
Sipgate, and also added a password. The phone is also in a DMZ, so not
protected by firewall.

When I then tried to use the phone later on, it wouldn't work, so I logged
on the web interface again, and saw a new interface (three tabs instead of a
single page, so the phone must have downloaded automatically an upgrade from
the manufacturer), and the provider details had changed. The phone wouldn't
connect anyway since I don't have an account with them.

I found all of this very strange. I changed the settings manually back to
Sipgate, and the phone is now working again...


"Ivor Jones" <> wrote in message
news:...
> Tom wrote:
>> Hi,
>>
>> I have a SIP phone (Grandstream BT 101), which I use with Sipgate.
>> However, yesterday, when I tried to use it, it wouldn't work. I
>> went to the settings page of the phone, and discovered that the
>> connection details had been changed. The provider was no longer
>> Sipgate but europasstelecom.com (many settings had been changed).
>>
>> I wonder if this is a bug following a self-firmware update, or if
>> some company hacked the phone to change the provider...
>>
>> Tom

>
> Interesting, not come across that before. I'll make some enquiries..! Had
> the firmware recently updated..?
>
> Ivor
>
>



 
Reply With Quote
 
Lee
Guest
Posts: n/a
 
      07-19-2005

"Andrew Gabriel" <> wrote in message
news:42dba60a$0$38044$.. .
> In article <42db928c$0$13702$> ,
> "Paul D.Smith" <> writes:
>>But does upgrading the firmware loose all customer settings? Is there no
>>facility for upgrading but restoring user configuration?

>
> Much to my surprise, upgrading (and then downgrading again)
> my sipura spa-3000 didn't lose any settings.
>


Out of interest - why did you downgrade?


 
Reply With Quote
 
Andrew Gabriel
Guest
Posts: n/a
 
      07-19-2005
In article <>,
"Lee" <> writes:
>
> "Andrew Gabriel" <> wrote in message
> news:42dba60a$0$38044$.. .
>> Much to my surprise, upgrading (and then downgrading again)
>> my sipura spa-3000 didn't lose any settings.

>
> Out of interest - why did you downgrade?


The version 3 firmware introduced and fault whereby all the
syslog messages are missing the PRI header so they aren't
usable. In the version 2 firmware, most of the syslog messages
are more correctly formed (a few only are missing the PRI header
and unusable).

Also, the version 3 firmware didn't fix the TCP window handling
problem which was the main reason for trying the upgrade. This
prevents the browser interface working properly when the browser
system advertises a large TCP window (i.e. probably something
over 32k, but not window scaling), and it is running across a WAN
or sufficient routers such that more than 32k of data gets
buffered across the network. It looks to me like the spa-3000 is
perhaps tripping on some associated 16bit arithmetic which needs
to be 32 bit arithmetic, screwing up its TCP sequence calculations,
and gets stuck in a TCP restransmit loop. If you have control of
the TCP window advertised from the browser system, knocking it
down to 20k is a workaround.

--
Andrew Gabriel
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Grandstream BT 101 TR UK VOIP 2 03-21-2006 12:58 PM
Grandstream phone dead - help me please vopa VOIP 13 01-09-2005 11:20 PM
Grandstream Sip phone - only 1 account per phone Boobie VOIP 10 12-27-2004 04:08 AM
Has anyone used those Grandstream VOIP phone?? SniperSquad VOIP 13 01-24-2004 12:38 AM
grandstream phone review Hugo Drax VOIP 0 10-08-2003 03:41 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57